- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
High level architecture questions (pre-sale)
Hi All,
I'm simply trying to see which Fortinet product I can use to
1) Aggregate / load balance 2-3 wan link. At a minimum 2 fiber from 2 source. I would like an LTE backup for a 3rd link. This is for a highly unstable environment
2) Having a firewall for protecting the network, connecting remotes sites with VPN links, all controlled by policies linked to AD groups.
Can I use one fortigate product for that or I need 2?
Thanks
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
"aggregate" or "load balance"?
With 2 ISPs, you cannot use a FGT to aggregate the WAN lines for higher throughput and redundancy. You would have to use a device which combines data streams on Layer 2. This would require a second identical device on the other side to de-interlace.
LB, sure, use SD-WAN (formerly WLLB, formerly...). This combines load balancing with monitoring, esp. remote monitoring, covering not only device failure and link failure but also route failure some hops further up.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
"aggregate" or "load balance"?
With 2 ISPs, you cannot use a FGT to aggregate the WAN lines for higher throughput and redundancy. You would have to use a device which combines data streams on Layer 2. This would require a second identical device on the other side to de-interlace.
LB, sure, use SD-WAN (formerly WLLB, formerly...). This combines load balancing with monitoring, esp. remote monitoring, covering not only device failure and link failure but also route failure some hops further up.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks Ede for the info.
I was looking at this type of product: https://www.mushroomnetworks.com/truffle/
and was wondering if fortigate could do the same.
From your comments, I could do load balance but not aggregate (bonding) which the truffle can do.
I have two "slow" fiber link on the project (2-5 Mbps), thus the need to aggregate.
For LB, SD-Wan can be used with a Fortigate 200E ?
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, SD-WAN is a feature of FortiOS v5.4 and (better) v5.6, independent of the hardware. It combines zones, routing, dead gateway detecting via pingservers in a neat way.
Bonding OTOH is not in the feature set of a Fortigate, but might be in other Fortinet products (which I do not know enough to name). Maybe check out FortiADC.
